TryHackMe | Walking An Application Walkthrough
Manually review a web application for security issues using only your browsers developer tools. Hacking with just your browser, no tools or scripts.
Link- https://tryhackme.com/room/walkinganapplication
Go to the website https://LAB_WEB_URL.p.thmlabs.com
Right click and view page source
What is the flag from the HTML comment?
![](https://cdn-images-1.medium.com/max/1000/1*vPzMoA4MSw0ctzh7oOpgwg.png)
Go to /new-home-beta to find flag
![](https://cdn-images-1.medium.com/max/1000/1*CzUHwIHM-rjcSH6YT7JgTg.png)
What is the flag from the secret link?
![](https://cdn-images-1.medium.com/max/1000/1*Riy-H7Bz5ulgr0S5n0592Q.png)
Go to /secret-page
![](https://cdn-images-1.medium.com/max/1000/1*DozUPP1VotDZcGNl3qu81Q.png)
What is the directory listing flag?
Go to /assets and then read flag.txt
![](https://cdn-images-1.medium.com/max/1000/1*Dsd48TLCdjKmtEdeQCLykw.png)
![](https://cdn-images-1.medium.com/max/1000/1*sNZRZgqzPePh0VAHi1rr4w.png)
What is the framework flag?
![](https://cdn-images-1.medium.com/max/1000/1*aqSB4xsY0Gt3yi2mxognag.png)
Go to the above link
![](https://cdn-images-1.medium.com/max/1000/1*6fKES3J8hs-0lIUt4DETEA.png)
Check the Change Log
![](https://cdn-images-1.medium.com/max/1000/1*Yhher5pSj09EaNa7T1gtnw.png)
Go to /tmp.zip and download the file. It will have the flag
What is the flag behind the paywall?
Follow the instructions mentioned to reveal the flag
![](https://cdn-images-1.medium.com/max/1000/1*P2U-xuYSXuCIQF5ou_opdQ.png)
![](https://cdn-images-1.medium.com/max/1000/1*dlwYdprXvR7mgja7NgDAZw.png)
What is the flag behind the paywall?
Follow the instructions mentioned to reveal the flag
![](https://cdn-images-1.medium.com/max/1000/1*44lqXOO3Yv-TL651BGzbkQ.png)
![](https://cdn-images-1.medium.com/max/1000/1*0Ku6OrVxutmHdEgeLJHPeA.png)
What is the flag shown on the contact-msg network request?
Follow the instructions mentioned to reveal the flag
![](https://cdn-images-1.medium.com/max/1000/1*b4_6-YudkLGiIz9F4F3ZFg.png)
![](https://cdn-images-1.medium.com/max/1000/1*Qkt7qjHWCRXfkAdDuJwxeQ.png)
![](https://cdn-images-1.medium.com/max/1000/1*WXEP89QmVXJ8MOBIxS2_bQ.png)
That’s it. See you in the next Room :)
Comments
Post a Comment